NetWin SurgeFTP 2.3a1

CPE Details

NetWin SurgeFTP 2.3a1
2.3a1
2007-08-23
19h16 +00:00
2014-02-27
23h33 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:netwin:surgeftp:2.3a1:*:*:*:*:*:*:*

Informations

Vendor

netwin

Product

surgeftp

Version

2.3a1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2013-4742 2013-08-09 19h00 +00:00 Buffer overflow in NetWin SurgeFTP before 23d2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string within the authentication request.
7.5
CVE-2007-3768 2007-07-15 19h00 +00:00 The mirror mechanism in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to cause a denial of service (restart) via a malformed response to a PASV command.
8.5
CVE-2007-3769 2007-07-15 19h00 +00:00 Cross-site scripting (XSS) vulnerability in the mirrored server management interface in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to inject arbitrary web script or HTML via a malformed response without a status code, which is reflected to the user in the resulting error message. NOTE: this can be leveraged for root access via a sequence of steps involving web script that creates a new FTP user account.
5.8